Share

Data encryption now urgent - expert

accreditation
Jay Radcliffe displays a radio device he uses to perform an attack on an insulin pump, taking control of the device wirelessly, at the annual Black Hat conference for digital self defence in Las Vegas. (Isaac Brekken, AP, file)
Jay Radcliffe displays a radio device he uses to perform an attack on an insulin pump, taking control of the device wirelessly, at the annual Black Hat conference for digital self defence in Las Vegas. (Isaac Brekken, AP, file)

Cape Town – The threat of cyber criminals makes encryption a necessity rather than optional, says a security expert.

Gemalto’s Breach Level Index indicated that there were 1 600 disclosed corporate breaches in 2015 as cyber criminals ramped up efforts to gain access to personal and financial data.

“Security leaders at organisations large and small need to admit that they are going to be breached - and then figure out what to do from there. What data is going to cause them massive reputational damage? What data, in the event its integrity is compromised, is going to kill their business?” said Neil Cosser, Identity and Data Protection manager for Africa at Gemalto.

He said that hackers have realised the value of personal data over financial information as a strategy to conduct illicit and illegal activities.

“Compare that to what happens when a digital attacker steals your credit card information: If the credit card's compromised, it's comparatively easy for that credit card to be rejected, stopped, and a new credit card issued,” said Cosser.

“Hackers, in short, understand that it’s way harder (or even impossible) to change your ID number than it is to cancel a credit card,” he added.

Reputational damage

READ: WhatsApp on collision course with governments - experts

Cosser said that encryption of data is a critical aspect of security to mitigate the severity of breaches.

“The technology is there. And the rationale for using it is simple: Breach prevention is dead. Our 2015 Breach Level Index showed over 1 600 disclosed breaches worldwide. That led to more than 700 million records being exposed. To put it simply, blocking breaches isn’t working.

“As we watch hackers hone in on data critical to our lives and our businesses, we need to develop a mind-set that accepts attackers will find a way in - but that our critical data is protected so it doesn’t make its way out,” he said.

In SA, few companies readily admit to breaches because of the fear of reputational damage, Panda Security said recently and less than half (41%) recognise the threat of ransomware, a Kaspersky Lab study found.

Cosser argued that the growth of Internet of Everything devices created multiple channels to allows potential hackers in to a home or corporate network.

READ: No company is immune from cyber attacks - expert

Hackers in 2014 demonstrated how to compromise a LIFX smart light bulb and Kaspersky researchers recently showed vulnerabilities in smart city road sensors.

“By making the shift from considering more extravagant (and expensive) ways to keep bad guys out to protecting core assets once a diligent hacker eventually gets in, information security leaders will begin thinking in a totally different way. They’ll begin to evaluate risk better and apply core information security controls, encryption, key management, and authentication,” Cosser argued.

“Even when the attacker breaks through, the locked box they find inside is way less useful than the sprawling flows of data they unlocked in the unencrypted past. And, while encryption is one of the most obvious strategies for preparing for a breach, only 48 of the data breaches in 2015 – less than 4% of all breaches – involved data that was encrypted to any degree,” he added.

Do you trust your data with South African companies? Let us know


- Follow Duncan on Twitter

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
18.83
+1.0%
Rand - Pound
23.52
+1.2%
Rand - Euro
20.14
+1.3%
Rand - Aus dollar
12.30
+0.8%
Rand - Yen
0.12
+2.3%
Platinum
922.80
-0.3%
Palladium
959.00
-3.2%
Gold
2,334.69
+0.1%
Silver
27.22
-0.8%
Brent Crude
89.01
+1.1%
Top 40
69,358
+1.3%
All Share
75,371
+1.4%
Resource 10
62,363
+0.4%
Industrial 25
103,903
+1.3%
Financial 15
16,161
+2.3%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders